Skip to content
Threat Intelligence

Pass-the-Hash Attacks: Mechanics, Risks and Mitigation

Attackers bypass password verification by reusing cryptographic hashes, rendering complex passphrase policies ineffective against lateral movement.

Pass-the-Hash Attacks: Mechanics, Risks and Mitigation
Illustration: Malware Brief
Quick answer

Pass-the-hash is a technique where an attacker uses a stolen cryptographic hash of a password to authenticate to remote systems. This bypasses the need to decrypt the password. It affects Windows environments using older protocols. Mitigation requires disabling legacy authentication methods and enforcing modern security standards.

The Mechanics of Reusing Credentials

Imagine a building where security guards do not ask for your key, but instead compare the shape of your key against a master mould stored in their office. If you steal that mould, you can open every door without ever possessing the original key. This is the core logic behind pass-the-hash attacks. In technical terms, a hash is a fixed-length string of characters generated by a mathematical function from input data, such as a password. The system stores this hash, not the password itself, for comparison during login.

When a user logs in, the system hashes the entered password and compares it to the stored value. If they match, access is granted. Pass-the-hash exploits this by intercepting the stored hash. The attacker does not need to reverse the hash to find the original password. Instead, they present the captured hash directly to the authentication service. The service accepts it as valid proof of identity. This allows the attacker to move laterally across the network without ever knowing the actual password.

AspectDetail
Core MechanismReusing a cryptographic hash instead of the plaintext password
Primary TargetMicrosoft Windows environments using NTLM or Kerberos
PrerequisiteLocal or domain administrator access to capture hashes
Key VulnerabilityReliance on legacy authentication protocols that accept hashes
Detection DifficultyHigh, as authentication logs show successful logins with no decryption errors
Primary MitigationDisabling legacy protocols and enforcing Credential Guard

How the Capture Occurs

For this attack to succeed, the attacker must first obtain the hash. This usually happens through initial compromise of a workstation or server. Malware designed for credential dumping searches the memory of the Security Account Manager process on Windows systems. This process holds the Local Security Authority Subsystem Service, which stores the hashes of accounts that have logged into that machine.

The attacker may use legitimate administrative tools or specialised malware to extract these values. Once captured, the hash is copied to the attacker's control machine. The original system remains unaware of the theft because no login attempt has occurred yet. The hash is now a portable credential. It can be used from any machine that has network access to the target system. This detachment means the attacker does not need to stay on the initial compromised host.

Common Forms and Protocols

Not all authentication methods are equally vulnerable. The risk depends heavily on the protocol in use. NTLM is a challenge-response authentication protocol used in Windows networks. It is the most common vector for pass-the-hash because it transmits the hash rather than the password. If an attacker captures an NTLM hash, they can replay it to authenticate to other systems that accept NTLM.

Kerberos is the default authentication protocol for modern Windows domains. It is more complex and generally more secure. However, it is not immune. An attacker with sufficient privileges can request a Ticket Granting Ticket using a stolen hash. This allows them to impersonate the user within the Kerberos ecosystem. The distinction is subtle but significant. While NTLM is often easier to exploit directly, Kerberos abuse requires a deeper understanding of ticket structures and domain policies.

Who Is Affected

This threat primarily targets organisations running Windows-based infrastructure. Any environment where users or services have administrative privileges is at risk. The impact scales with the privilege level of the compromised account. A standard user hash offers limited lateral movement. A domain administrator hash grants access to nearly every system in the domain.

Service accounts are particularly dangerous targets. These accounts often have high privileges and are rarely logged out, keeping their hashes in memory for extended periods. If a service account is compromised, the attacker gains persistent access. This is why least privilege principles are critical. Reducing the number of accounts with administrative rights limits the value of any single captured hash.

What People Usually Get Wrong

A common misconception is that strong passwords prevent pass-the-hash attacks. This is incorrect. The attack bypasses password verification entirely. Whether the password is "password123" or a forty-character passphrase, the hash is the only thing that matters. Increasing password complexity does not add resistance to this specific technique.

Another error is assuming that encryption at rest solves the problem. If the hash is extracted from memory, encryption on the disk is irrelevant. The attacker operates in the active session space. Security teams often focus on protecting the password, but the hash is the actual credential in this context. Shifting focus to hash protection and protocol hygiene is necessary.

See also: Detecting Credential Dumping: Signals, Logs and Blind Spots · How to Implement Red Teaming: A Practical Step-by-Step Framework

Infographic: Pass-the-Hash Attacks: Mechanics, Risks and Mitigation. Credential theft does not require password decryption to enable lateral movement within a network. Legacy authentication protocols remain the primary vector for this attack, even in modern infrastructure. Disabling specific legacy
Infographic: Pass-the-Hash Attacks: Mechanics, Risks and Mitigation. Free to share with a link to Malware Brief.

Reducing the Risk

Mitigation requires a shift in authentication architecture. The most effective step is disabling legacy authentication protocols. NTLM should be blocked or severely restricted where possible. Modern authentication methods do not transmit hashes in a reusable format. Forcing the use of these modern protocols removes the vector for hash replay.

Microsoft’s Virtualisation-Based Security features, specifically Credential Guard, provide a strong defence. Credential Guard isolates the LSASS process and protects the hashes from being read by malware. Even if an attacker gains administrator access, they cannot easily extract the hashes. This adds a hardware-dependent layer of protection that software-only solutions cannot match.

Regular auditing of administrative rights is also necessary. Identify which accounts have local or domain admin privileges. Remove unnecessary permissions. Monitor for authentication events that use legacy protocols. These logs provide early warning signs of potential abuse. Combining protocol restriction with privilege reduction creates a robust defence.

Related concepts such as remote desktop abuse often accompany this technique, as attackers use stolen hashes to open remote sessions. Understanding scheduled task abuse is also relevant, as attackers may use these tasks to persist after initial access. While threat actors may use various methods, the underlying principle of credential reuse remains constant. This differs from hacktivism, which often relies on public exposure rather than lateral movement. For deeper analysis of network behaviour, reviewing beaconing patterns can help identify the initial compromise that leads to hash theft. Finally, red teaming exercises should include pass-the-hash scenarios to test your defences.

Key takeaways

  • Credential theft does not require password decryption to enable lateral movement within a network.
  • Legacy authentication protocols remain the primary vector for this attack, even in modern infrastructure.
  • Disabling specific legacy protocols is more effective than increasing password complexity for this threat.
Bottom line

Pass-the-hash attacks bypass password strength by reusing cryptographic hashes, making protocol hygiene more critical than complexity. Disable legacy authentication protocols and enforce Credential Guard to eliminate the primary attack vector.

Frequently asked questions

Can antivirus software stop a pass-the-hash attack?

Antivirus may detect the tools used to capture hashes, but it cannot stop the authentication itself. The attack relies on legitimate system functions, so prevention requires architectural changes like disabling legacy protocols.

Does changing a password stop an attacker with a stolen hash?

Yes, resetting the password invalidates the old hash. However, if the attacker has already moved laterally or established persistence, resetting the password does not remove their access. You must also check for active sessions and remove unauthorized access.

Are Linux systems vulnerable to pass-the-hash?

Linux systems typically use different authentication mechanisms that do not store reusable hashes in the same way. While credential theft is possible, the specific pass-the-hash technique is primarily a concern for Windows environments using NTLM or Kerberos.

How do I know if my network is being targeted?

Look for successful authentication events using legacy protocols from unusual source machines. Monitor for lateral movement patterns where a user account accesses multiple servers in a short time. These indicators suggest credential reuse.

How this guide was produced: written by the Malware Brief editorial team with AI assistance, checked against the public references listed below, and reviewed when the facts change. See our editorial policy or report an error.

Further reading

  1. FIRST: Forum of Incident Response and Security Teams
  2. MITRE ATT&CK
  3. MITRE D3FEND
pass-the-hash attackspass-the-hashcredential theftwindows security

Related stories

Phishing Kits: Definition, Mechanics and Operational Reality

Phishing kits are pre-packaged criminal toolsets that standardise deception, allowing attackers to bypass security filters by mimicking trusted interfaces with surgical precision.

Cybersecurity news without the noiseDaily Briefing